
[Logistics Operators (Land Freight Transport and Port Transportation)] How Incident Response Will Change with the Enforcement of the Cyber Response Capability Enhancement Act
July 22, 2026
Author of this article
President and CEO
Takaaki Kanetsuki
The public-private partnership provisions of the so-called “Cyber Response Capability Enhancement Act” (official title: Act on the Prevention of Damage Caused by Unauthorized Acts Against Important Computers), which was enacted in May 2025, will take effect in October 2026.The covered critical infrastructure sectors include truck transportation (land freight transport) and port transportation; designated operators will be legally required to register their system assets and report cyber incidents to the government.
For the logistics industry, this series of regulatory tightening measures is not someone else’s problem.
In fact, we are “directly affected parties.” The ransomware attack that occurred at a container terminal in the Port of Nagoya in July 2023 (Reiwa 5) served as the direct catalyst for designating the port sector as critical infrastructure and adding port transportation to the Core Infrastructure System. At the heart of the system’s design philosophy lies an actual incident that occurred in the logistics sector.
In this article, we will examine the practical incident response measures required of land freight and port transport operators, using a case from the Port of Nagoya as a starting point, and organize the discussion into three categories: laws, business regulations, and guidelines.
The Starting Point for Everything: What Happened During the System Failure at the Port of Nagoya
In July of Reiwa 5, the Nagoya Port Unified Terminal System (NUTS) was shut down due to a ransomware attack, bringing container loading and unloading operations to a halt for more than two full days. The shutdown of this port—which boasts one of the largest container handling volumes in the country—has had widespread repercussions extending beyond the port itself, resulting in trailer backlogs and logistics delays.
At that time, even while the system was down, some cargo handling operations with vessels continued manually on-site. During the recovery phase, the procedure involved verifying the consistency between the data and the actual inventory information, and then resuming operations sequentially, starting with the terminals that were ready.
While it is not impossible to “manage manually even if the system goes down,” this approach falls far short of normal processing capacity, and the fact that a time-consuming task—verifying data consistency—awaits during recovery serves as the starting point for considering incident response in logistics.
The report (January Reiwa 6) by the review committee established in response to this incident outlined three institutional measures: measures under the Basic Act on Cybersecurity (adding ports to the list of critical infrastructure sectors and formulating guidelines); measures under the Port and Port Transportation Business Act (adding security items to business plan reviews); and measures under the Act on the Promotion of Economic Security (adding port transportation to the critical infrastructure framework).
All subsequent systems are an extension of this summary.
Legal Requirements: Notifications and Incident Reporting
The entities directly subject to the Strengthening Act are specific social infrastructure operators (core infrastructure operators) designated under the Economic Security Promotion Act; as of April 1, Reiwa 8, a total of 257 such operators have been designated across all sectors.
The designation of logistics-related entities is a relatively recent development. In the port transportation sector, following a legislative amendment (enacted in May Reiwa 6), the system came into effect in April Reiwa 7, and operators were designated on May 1 of that year. After a transitional period, prior notification and review procedures regarding the outsourcing of Terminal Operation System (TOS) implementation and maintenance began on November 2, Reiwa 7.
In the land freight transport sector as well, operators were designated on July 14, Reiwa 7, following amendments to the ministerial ordinance defining the scope of applicable facilities.
The Strengthening Act imposes the following obligations on designated operators: They must report to the government the vendor names and product information for “specified critical computers” among the information systems involved in core business operations; and they must report incidents in the event of a cyberattack.
Regarding the reporting framework, the draft guidelines for implementation presented to the Cabinet Office’s Expert Panel outline a two-stage reporting process.Upon becoming aware of an incident, an organization must promptly issue a “preliminary report” and submit a “detailed report” within 30 days. In both cases, organizations are only required to report the information known at that time; they are not expected to provide a complete root cause analysis during the initial response phase. The scope of reporting includes not only traces of “specified unlawful acts,” such as unauthorized access, but also related events. The system is designed so that the reporting obligation begins as early as the warning signs stage.
The procedures for handling such incidents in cloud environments have also been clarified. In the case of SaaS or PaaS (related to middleware or operating systems), an incident is deemed to have been “acknowledged” at the time the cloud service provider issues a notification. Businesses that use cloud services for systems such as dispatch management, operations management, warehouse management (WMS), and transportation management (TMS) must establish in advance a designated point of contact for receiving notifications of outages or security breaches from vendors, as well as procedures for incorporating such notifications into their reporting workflow.
The penalties cannot be overlooked either. Violating the reporting obligation and failing to comply with a corrective order issued by the regulatory authority is punishable by a fine of up to 2 million yen, while failing to comply with a request to submit documents or other materials is punishable by a fine of up to 300,000 yen.
Furthermore, one aspect that the logistics industry should be particularly mindful of is the ripple effect on non-designated operators. It has been pointed out that IT vendors and group companies entrusted with the operation of specified critical computers—as well as equipment owned by subcontractors, depending on the system configuration—may also be subject to these regulations.
In the logistics sector, where a multi-tiered structure of prime contractors and subcontractors is the norm and system and data integration among businesses is advancing, it is entirely possible that a company could be drawn into the system as a “subcontractor or connected party of a designated operator”—even if it has not been designated itself.
The review process has “already” begun for port transportation.
Even before the Enforcement Act takes effect, a mechanism with binding force is already in place in the port transportation sector. Under the amended Enforcement Regulations of the Port Transportation Business Act (effective March 31, Reiwa 6), business plans submitted for review when entering the general port transportation business—among other scenarios—are now required to include an overview of the TOS and details regarding information security measures. This mechanism allows the national government to verify the status of TOS security measures through the review of business plans.
Unlike the guidelines, which are merely recommendations, this is a mandatory requirement for business plan applications. In the world of port transportation, it can be said that security measures have already taken a step forward, evolving from “something that is desirable to do” to “a prerequisite for conducting business.”
"Practical Incident Response" as Outlined in the Guidelines
The Ministry of Land, Infrastructure, Transport and Tourism has established three safety guidelines for the logistics sector—covering “Freight Truck Transportation,” “Warehousing,” and “Vessel Operations” (all first editions enacted in April Reiwa 6)—as well as the “Safety Guidelines for Ensuring Information Security in the Port Sector” for the port sector. The port sector guidelines have undergone repeated revisions since their first edition in April Reiwa 6, and the third edition was published in May Reiwa 8.The fact that the first edition was released just nine months after the incident at the Port of Nagoya, and that it has been revised annually since then, demonstrates the government’s sense of urgency regarding this sector.
Although these guidelines are merely recommended standards that do not involve government audits, they provide a practical foundation for fulfilling reporting obligations under the Enhanced Act. Here are some key points to keep in mind from an incident response perspective.
Establishing a System That Involves Senior Management
Based on the recognition that it is difficult to prevent all cyberattacks—which are becoming increasingly complex and sophisticated—the guidelines for the port sector call for a response involving the entire organization, including senior management, and for strengthening incident response systems through a combination of proactive risk management and crisis management. The starting point is the understanding that this is not an issue that can be handled solely by on-site system administrators.
Notification and Documentation When an Incident Occurs
The guidelines for the port sector outline specific action steps, including contacting the Ministry of Land, Infrastructure, Transport and Tourism and the police in the event of an attack, and documenting the situation chronologically as it unfolds. These chronological records serve as foundational data directly relevant to both subsequent investigations into the cause and the preliminary and detailed reports required under the Enhanced Security Act. It is essential to establish a system during peacetime that ensures recording begins the moment an anomaly is detected.
Preparing for Ransomware
The guidelines clearly state that when a ransom is demanded in a ransomware attack, it is strongly recommended to refrain from paying in order to prevent further attacks. They also require that backups be taken properly and stored in a location separate from the active system. The reason the Nagoya Port incident was ultimately resolved was that the data was recovered; therefore, how backups are handled determines the very success or failure of incident response.
Pre-Planning of Recovery Procedures
As the situation at the Port of Nagoya demonstrates, recovery is not simply a matter of “restarting the system and calling it a day.” The recovery phase involves tasks unique to that stage, such as verifying the consistency between data processed manually during the outage and the data in the system, as well as making decisions on the phased resumption of operations at each terminal and facility. If your company switches to manual operations during a system outage, it is highly valuable to identify in advance exactly which data sets need to be reconciled.
What to Do Before the Law Takes Effect
With the law set to take effect in October 2026, the actions that designated (or potential designated) businesses need to take are becoming clearer.
Asset Inventory
We will identify specific critical computers and peripheral devices that may be subject to reporting requirements. In the case of port transportation, the focus will be on the TOS; for land freight transportation, it will be dispatch and operations management systems; and for warehousing, it will be systems such as the WMS. We will identify which systems would directly lead to business disruption by working backward from the magnitude of the impact.
Establishing a Reporting Process
Incorporate the definition of “recognition” (including notifications from cloud vendors), the procedures for drafting and approving preliminary reports, and the investigation framework for submitting detailed reports within 30 days into the emergency response plan. Designing the notifications to the Ministry of Land, Infrastructure, Transport and Tourism and the police—as required by the guidelines—along with chronological records and the statutory reports under the Enhanced Act separately will cause confusion on the ground. Let’s consolidate these into a single system so that “once a record is created, it can be reused for reports to all relevant parties.”
Organization, Including Business Partners
Confirm in advance who is responsible for contacting whom and when an incident occurs, including contractors for your company’s systems, shippers, and partners involved in data exchange—such as prime contractors and subcontractors. As the incident at the Port of Nagoya demonstrated, logistics incidents do not result in damage limited to a single company. Being prepared for both scenarios—where your company is the source of the incident and where you are affected by a failure at a connected party—is a critical precaution unique to this industry.
Some details of the law will be finalized through cabinet orders, ministerial ordinances, and operational guidelines prior to its enforcement; therefore, items referred to as “drafts” in this article are subject to change. Please refer to the official documents published by the Cabinet Office (Cyber Security and Economic Security Divisions) and the Ministry of Land, Infrastructure, Transport and Tourism for the latest information.
And so, Incident Lake

As we have seen so far, the real burden of complying with the Enhanced Security Act lies not so much in establishing rules during normal times as in “the practical response beginning the very moment an incident occurs.”When you consider the need to organize the facts as they are identified and issue a preliminary report promptly, maintain a chronological record while responding to the incident, compile a detailed report within 30 days, and manage reports to multiple contacts—such as the Ministry of Land, Infrastructure, Transport and Tourism, the police, and business partners—it becomes clear, as demonstrated by the Port of Nagoya incident, that logistics incidents have a wide-ranging impact, leaving the on-site response team with almost no capacity left for reporting duties.
Incident Lake is an incident management platform that supports this entire process. It automates everything from reporting an incident to recovery, as well as the creation and management of reports, allowing staff to focus their time on what truly matters: “resolving the immediate issue and keeping logistics running.” Now that time-sensitive reporting requirements—such as preliminary and detailed reports—are becoming standard practice, we recommend transitioning your reporting and record-keeping systems to a model that doesn’t rely on individual effort.
Reference Materials
Ministry of Land, Infrastructure, Transport and Tourism, “Safety Guidelines for Ensuring Information Security in the Port Sector (3rd Edition) – Introduction” (May 13, Reiwa 8) https://www.mlit.go.jp/kowan/content/001880210.pdf
Ministry of Land, Infrastructure, Transport and Tourism, “Q&A Regarding the ‘Safety Guidelines for Ensuring Information Security in the Port Sector (3rd Edition)’” (May 13, Reiwa 8) https://www.mlit.go.jp/kowan/content/001891691.pdf
Ministry of Land, Infrastructure, Transport and Tourism, “Safety Guidelines for Ensuring Information Security in the Logistics Sector (Warehouses), 1st Edition” (April 18, Reiwa 6)
Ministry of Land, Infrastructure, Transport and Tourism: Information Security (List of Safety Guidelines by Sector) https://www.mlit.go.jp/sogoseisaku/jouhouka/sosei_jouhouka9999.html
Ministry of Land, Infrastructure, Transport and Tourism: Economic Security (Systems for Ensuring the Stable Provision of Core Infrastructure Services; Status of Designation of Specified Social Infrastructure Operators) https://www.mlit.go.jp/sogoseisaku/jouhouka/sosei_jouhouka_fr1_000028.html
Cabinet Office: “System for Ensuring the Stable Provision of Critical Infrastructure Services” https://www.cao.go.jp/keizai_anzen_hosho/suishinhou/infra/infra.html
Director-General for Policy Coordination, Cabinet Office (in charge of Cybersecurity): “Draft Guidelines for the Enforcement of the Act on Strengthening Cyber Response Capabilities (Public-Private Partnership)” (December Reiwa 7) https://www.cao.go.jp/cybersecurity/kaigi/pdf/04shiryo05.pdf
Nikkei CrossTech: “Cyber Response Capability Enhancement Act to Take Effect in October; Risk of Being Excluded by Business Partners” (2026) https://xtech.nikkei.com/atcl/nxt/column/18/00989/042300207/
Author of this article
President and CEO
Takaaki Kanetsuki
SIGQ Inc. Representative Director
Graduated from the University of Tsukuba Graduate School; specializes in databases and distributed systems.
An engineer who handles unstructured, real-time operational data—essential in the AI era.
Joined Money Forward, Inc. as a new graduate. Engaged in management and development at various development sites, including overseas locations, such as a secondment to the Vietnam office.
Joined Played Inc. in 2022 and is responsible for Platform Engineering. Involved in the development of large-scale distributed data systems.
Founded SIGQ Inc. in 2024.
List of Helpful Articles


